[VOIPSEC] Oreka vulnerability

Candace Holman candace_holman at harvard.edu
Mon Mar 13 17:18:59 CST 2006


Isn't it ironic?

06.10.15 CVE: CVE-2006-0912
Platform: Unix
Title: Oreka RTP Packet Handling Remote Denial of Service

Description: Oreka is a freely available, open-source audio recording
application. Oreka is susceptible to a remote denial of service
vulnerability. This issue is due to the application's failure to
properly handle unspecified sequences of RTP packets. Oreka versions
prior to 0.5 are affected by this issue.
Ref: http://oreka.sourceforge.net/about/news?id=2006-02-16/0.5-release

http://secunia.com/advisories/19095/
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0912

Candace







More information about the Voipsec mailing list